CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Unlock Lite subscribe-to-unlock-lite allows PHP Local File Inclusion.This issue affects Subscribe to Unlock Lite: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This issue affects Fana: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.15%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This issue affects Zota: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.15%
View Details
9.1

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.04%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Bookory bookory allows PHP Local File Inclusion.This issue affects Bookory: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.15%
View Details
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Blind SQL Injection.This issue affects Brands for WooCommerce: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.04%
View Details
9.1

Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse Form: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.04%
View Details
9.1

Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brave: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.04%
View Details
9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nawawi Jamili Docket Cache docket-cache allows PHP Local File Inclusion.This issue affects Docket Cache: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.15%
View Details
9.1

Server-Side Request Forgery (SSRF) vulnerability in bdthemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Server Side Request Forgery.This issue affects Prime Slider – Addons For Elementor: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.04%
View Details
9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.04%
View Details
9.8

Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object Injection.This issue affects Icegram Express Pro: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.05%
View Details
9.1

Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects 6Storage Rentals: from n/a through

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.04%
View Details
9.8

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in Dompdf, and missing escape in the 'template.php'…

Published: Dec 24, 2025
Modified: Dec 29, 2025
EPSS: 0.53%
View Details
9.6

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2 and prior, an RCE vulnerability exists in useMarkdown.ts, where the markdown-it-mermaid plugin is initialized with securityLevel: 'loose'. This configuration explicitly permits the rendering of HTML tags within Mermaid diagram nodes. This issue has not…

Published: Dec 23, 2025
Modified: Jan 07, 2026
EPSS: 0.04%
View Details
9.3

LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions do not escape dictionaries with 'lc' keys when serializing free-form dictionaries. The 'lc' key is used internally by LangChain to mark…

Published: Dec 23, 2025
Modified: Jan 13, 2026
EPSS: 0.08%
View Details
9.9

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions to execute arbitrary commands as root on managed servers. Database names used in backup operations are passed…

Published: Dec 23, 2025
Modified: Jan 07, 2026
Product: coollabs coolify
EPSS: 0.47%
View Details
9.8

A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Handler. Performing manipulation of the argument Username results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.

Published: Dec 23, 2025
Modified: Dec 30, 2025
Product: tenda wh450_firmware
EPSS: 0.09%
View Details
9.8

A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/PPTPClient of the component HTTP Request Handler. Such manipulation of the argument netmsk leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed…

Published: Dec 23, 2025
Modified: Dec 30, 2025
Product: tenda wh450_firmware
EPSS: 0.09%
View Details
9.8

A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit of the component HTTP Request Handler. This manipulation of the argument page causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and…

Published: Dec 23, 2025
Modified: Dec 30, 2025
Product: tenda wh450_firmware
EPSS: 0.09%
View Details
9.8

A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.

Published: Dec 23, 2025
Modified: Dec 30, 2025
Product: tenda wh450_firmware
EPSS: 0.09%
View Details
9.8

Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in sensitive data disclosure and backend compromise.

Published: Dec 23, 2025
Modified: Jan 06, 2026
Product: puneethreddyhc event_management
EPSS: 0.04%
View Details
9.8

Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.

Published: Dec 23, 2025
Modified: Jan 06, 2026
Product: cadmium-cms cadmium_cms
EPSS: 0.05%
View Details
9.8

NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data tampering.

Published: Dec 23, 2025
Modified: Jan 15, 2026
Product: nvidia isaac_launchable
EPSS: 0.08%
View Details